The debit does not look like a crime scene.
It looks like a vendor charge. Maybe a marketing fee. Maybe a software subscription someone forgot to cancel. The amount is not outrageous. The name is vague, but not alarming. So it sits there.
That is the danger.
On July 20, 2026, the U.S. Department of Justice announced that Jeremy Todd Briley, an Oregon payment processing broker, was sentenced to three years in prison for a wire fraud scheme involving fraudulent bank debits.
According to DOJ, Briley helped sham merchant companies get and keep access to payment processors. Those companies claimed to provide online marketing services to businesses. Prosecutors said they were actually using those processing relationships to debit victims’ business bank accounts without authorization.
DOJ said the scheme caused more than $14 million in unauthorized debits and attempted debits between February 2017 and December 2023. Prosecutors also said Briley knew the debits were unauthorized, received repeated warnings about them, concealed the activity, and helped arrange for a payment processor to deceive banks by manipulating return rates.
Source: U.S. Department of Justice, “Oregon Payment Processing Broker Sentenced for $14 Million Dollar Wire Fraud Scheme,” July 20, 2026: https://www.justice.gov/opa/pr/oregon-payment-processing-broker-sentenced-14-million-dollar-wire-fraud-scheme
The Part Business Owners Should Look At Closely
This case is not really about a password. It is about access.
A lot of business owners think of the bank account as protected unless someone steals login credentials or talks an employee into sending money. But ACH debits create another risk: money can be pulled from the account, and the transaction may look ordinary enough to pass a quick review.
That is where this case gets useful.
The alleged cover story was not strange. Online marketing services. Merchant accounts. Payment processing. Those are normal business words. They belong on invoices and statements every day.
Fraud likes that kind of cover. It does not have to explain much.
The Charge That Gets Waved Through
A bad debit can survive because everyone is busy.
The owner assumes the bookkeeper knows what it is. The bookkeeper assumes the owner approved it. The amount looks small enough to wait until month-end. The descriptor is unclear, but unclear descriptors are everywhere now.
That is how a fake charge earns time.
The warning sign is not always a huge withdrawal. Sometimes it is the transaction no one can tie back to a contract, invoice, approval, or known vendor.
If the answer is “probably something,” keep digging.
What This Case Teaches
The DOJ allegations point to a few controls worth tightening.
Check ACH debits every business day. Do not wait for the monthly statement. Look for unfamiliar merchant names, vague billing descriptors, small recurring charges, and amounts that do not match known vendors.
Keep a vendor list that matches the bank statement. Include the vendor name, the billing descriptor, the expected amount, the billing schedule, the account charged, and the person inside the business who owns that relationship.
Ask your bank about ACH debit blocks or filters. Some banks allow businesses to limit who can debit an account. That may not work for every operating account, but it can be a strong control for payroll, reserves, or accounts with limited activity.
Use alerts that catch small trouble. A large-dollar alert is useful, but fraud does not always start large. Lower alerts can catch the test debit before the pattern grows.
Separate accounts when it makes sense. If one account holds everything and pays everything, a bad debit has more room. Payroll and reserve funds deserve tighter exposure.
If You Spot One
Do not wait for the second charge.
Call the bank. Save screenshots. Pull statements. Ask about dispute deadlines, ACH protections, and whether the account needs a block, filter, or replacement.
Then search backward. Look for the same descriptor, similar amounts, related merchant names, or small test debits. The first charge you notice may not be the first charge that happened.
The recovery question matters. But the control question matters more: how did this debit get through, and what would catch it faster next time?
The Detect-A-Fraud Read
This case is a reminder that fraud does not always need drama. It does not always need a hacked inbox or a stolen password.
Sometimes it needs a bank account with loose debit exposure, a vague merchant descriptor, and a business that is too busy to question a small charge.
Watch the pull side of your bank account, not just the payments you send out. Know who is allowed to debit you. Match every unfamiliar charge to proof. Treat “probably” as unfinished work.
Because the debit that looks boring is sometimes the one worth investigating.